Back

LOW

cups: password disclosure via debug log

Published Jun 2, 2008

Description

The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of cups as shipped with Red Hat Enterprise Linux 3, 4, or 5.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 2, 2008
Updated Aug 7, 2024
Reserved Feb 26, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 28, 2008